Senior Threat Research Engineer – Taiwan
Core
Lead the development of security detections for identity threats, malicious activity, and emerging attack patterns across cloud and SaaS environments.
Role type
Senior Threat Research Engineer (Detection Engineering)
Builds
Production detection rules, behavioral models, and scalable detection pipelines for SaaS security platform
Domain
Cybersecurity, Cloud Security, SaaS Security, Identity Threats
Deliverable
production ML models | product features
Required skills
Threat research, detection modeling, data analysis, rule authoring, incident response, threat hunting, security analytics, cloud security knowledge, identity threat expertise, large security dataset analysis, detection lifecycle management, detection quality measurement
Preferred skills
Identity security, SaaS security, cloud detection and response, SIEM, UEBA, EDR, XDR, MITRE ATT&CK frameworks, detection-as-code systems, machine learning, anomaly detection, generative AI, incident response investigation, team scaling
Technologies
OAuth, cloud telemetry, authentication activity, application logs, behavioral models, statistical methods
Responsibilities
Research cloud, identity, and SaaS threats and translate attacker behaviors into actionable detection opportunities; Develop threat models covering attack paths, adversary techniques, identity misuse, suspicious activity, and control failures; Design, author, test, and maintain detection rules and behavioral detection models; Define telemetry, enrichment, correlation, and historical context required to support effective detections; Partner with platform and data engineering teams to build scalable detection capabilities and production processing pipelines; Develop frameworks for detection testing, simulation, coverage measurement, versioning, release management, and ongoing tuning; Measure and improve detection precision, recall, explainability, performance, and customer value; Investigate false positives and false negatives, identify their root causes, and improve detection logic and underlying data quality; Map detection coverage to relevant threat frameworks, attack techniques, product use cases, and customer risks; Monitor the evolving threat landscape and rapidly develop coverage for new techniques and vulnerabilities; Partner with Product Management and Customer Success to understand customer environments, workflows, and detection requirements; Create clear documentation explaining detection intent, supporting evidence, expected behavior, limitations, and recommended response actions; Collaborate with teams across Taiwan, the US, the UK, and Australia to build a unified global detection program
Seniority
Senior, hands-on IC with leadership responsibilities